PT-2026-24254 · Oneuptime · Oneuptime

Iconnnjka

·

Publicado

2026-03-10

·

Atualizado

2026-03-17

·

CVE-2026-30958

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OneUptime versions prior to 10.0.21
Description OneUptime is a solution for monitoring and managing online services. A path traversal issue exists in the /workflow/docs/:componentName API endpoint, allowing unauthenticated reading of arbitrary files from the server filesystem. The componentName route parameter is directly concatenated into a file path and passed to the res.sendFile() function within the orker/FeatureSet/Workflow/Index.ts file without any sanitization or authentication checks.
Recommendations Update to version 10.0.21 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30958
GHSA-P2WH-9PW8-HVFF

Produtos afetados

Oneuptime